Troubleshooting Tip: FortiGate HA Cluster Fails to Synchronize after firmware upgrade to FortiOS v7.6.7 and v8.0.0
Description | This article describes the issue of a FortiGate High Availability (HA) cluster failing to synchronize after a firmware upgrade to FortiOS v7.6.7 or v8.0.0. |
Scope | Â FortiGate v7.6.7 and v8.0.0. |
Solution | After upgrading to FortiOS 7.6.7 or 8.0.0, the HA cluster may report an out-of-sync status due to a checksum mismatch for 'user.krb-keytab' between the HA members. This checksum can be verified in FortiGate GUI under FortiGate GUI -> System -> HA by hovering the mouse over the unsynchronized device to see the tables that are out of sync and the checksum values, or in FortiGate CLI by running the following command in both HA members:Â
As a result, the 'ser.krb-keytab' checksum may differ between HA members following the firmware upgrade, even though the configuration itself has not changed. This issue will be fixed in the upcoming FortiOS releases v7.6.8 and v8.0.1. |
